Law firms SECTOR

Cyber Essentials for law firms, before the contract asks twice.

The firm that answers with a certificate stops writing essays.

Since 1 October 2025, a criminal legal aid contract (the 2025 Standard Crime Contract) requires a valid Cyber Essentials certificate. The PII proposal form and the client panel questionnaire ask the same questions with different letterheads.

We implement Cyber Essentials, CE+ and ISO 27001 controls for firms of 30-100 staff. An accredited assessor certifies. Your MSP stays.

CE+ from £2,950 · ISO 27001 from £15,000 · assessor and audit fees separate
A control checklist and evidence pack on a desk
1 OCT 2025 26 APR 2026 LAA REQUIRES CE THE SCHEME TIGHTENS THE DEADLINES LIVE IN YOUR CONTRACTS

A CERTIFICATE ANSWERS THE QUESTIONNAIRE ONCE

01

Who this is for

The queue is run. Nobody owns the evidence.
The firm

Law firms of 30-100 staff. An MSP runs the queue. Nobody owns the evidence. The managing partner, the COO, or the practice director has become the person the cyber questions land on.

Criminal practices with a legal aid contract to keep. Civil and commercial firms whose PII renewal, lender panel, or corporate client has started asking for certificates instead of assurances.

The signs
  • The legal aid contract now asks for a certificate, and the renewal has a date on it.
  • The PII proposal form asks about MFA, patching, backups and access control, and the premium listens to the answers.
  • A panel or client questionnaire has landed and nobody owns the answer.
  • The MSP runs the queue. Nobody signs the pack.
02

The contract clock

Two dates, one questionnaire
The deadlines

The deadlines live in your contracts.

  • Since 1 October 2025 the Legal Aid Agency requires a valid Cyber Essentials certificate for practices holding a 2025 Standard Crime Contract. The contract makes it a condition.
  • From 26 April 2026 the Cyber Essentials scheme itself gets harder: MFA on every cloud service, critical patches inside 14 days. A certificate that renewed easily last year can fail this year.
  • Professional indemnity insurers put the same controls on the proposal form, and the answers shape the premium.
  • Panel and client audits increasingly ask for CE+, and for ISO 27001 at the top end.
03

The routes in

The sprint, the seat, the AI angle
The sprint

CE+ / ISO 27001 sprint

We implement. An accredited assessor certifies. Scope the estate: the practice management system, the document store, the remote access, the personal devices that crept in. Then the controls the LAA and the insurer actually check: MFA, patching, access, backups. ISO 27001 when a panel or a corporate client requires it. A pack the partner who signs things can read.

CE+ FROM £2,950 · ISO 27001 FROM £15,000

The seat

Fractional Head of IT & AI

One named senior who owns the gap list, signs the pack, and answers the partner who asks how safe the firm actually is. The MSP stays and does what it does well: much of the remediation lands in their queue anyway. We scope it, own it, and evidence it.

FROM £4,750 A MONTH

The AI angle

Say yes to AI, safely

A law firm can say yes to AI safely once the controls are real. Confidentiality, privilege and the document store are exactly what the CE+ and ISO work locks down. On that footing, an AI Opportunity Audit shows where AI pays before you spend, and Microsoft Copilot readiness prepares the tenant.

AUDIT FROM £4,950 · COPILOT FROM £7,500

04

How it runs

Diagnose. Deliver. Decide.
01

Diagnose

We sit with the partner who signs things, the practice manager, and the MSP. The certificate requirement comes first. The server tour can wait.

02

Deliver

Controls implemented, evidence gathered, the assessor booked. A board-readable outcome: what passed, what was fixed, what still carries a risk.

03

Decide

Certificates lapse when nobody owns them. The fix is one or two days a week from someone who already knows the estate. Or keep the gains and run it yourselves: either way the firm is stronger.

05

What you leave with

The pack, in plain words
The pack
The certificate path

Controls in place, and an accredited assessor booked to certify.

The evidence pack

Documents, owners and dates, written so a signing partner needs no translation.

The questionnaire answers

The PII form and the panel audit answered once, from one source.

An owner

A named senior accountable for the gap list, and for closing it.

06

The price

Fixed, in writing, before we start
Fixed fee

CE+ from £2,950 · ISO 27001 from £15,000.

Cyber Essentials Plus readiness and remediation from £2,950, fixed. ISO 27001 implementation from £15,000, scoped at diagnose. ISO 42001 readiness from £6,500 when AI governance reaches the questionnaire. Assessor and audit fees are separate, paid to the accredited bodies. Fixed pieces of work, priced in writing before anything starts. The full scope sits on the CE+ / ISO 27001 sprint page.

There is no monthly subscription on this page. After the sprint, the Head of IT seat (from £4,750 a month) is how the certificate stays owned, if the seat needs filling.

Also from the framework

All six services, and the framework they belong to, are on one page.

07

FAQs

Asked before, answered here

Is Cyber Essentials really required for legal aid work?

For criminal legal aid, yes. Since 1 October 2025 the Legal Aid Agency has required practices holding a 2025 Standard Crime Contract to hold a valid Cyber Essentials certificate as a condition of the contract. If that renewal is coming, the readiness work is this page.

We do no legal aid work. Why would we certify?

The PII proposal form, the client panel audit, and the lender or corporate client questionnaire all ask the same questions Cyber Essentials answers. A certificate is the short way to stop answering them one form at a time.

What changes on 26 April 2026?

MFA extends to every cloud service and critical patches must land inside 14 days. A certificate that renewed easily under the old scheme can fail under the new one, so start the remediation ahead of the renewal.

Our MSP looks after IT. Can they not do this?

Keep the MSP. Most of the fixes land in their queue anyway. What we add is scope, ownership and evidence, with a named senior accountable for all three.

Do you certify Cyber Essentials or ISO 27001 yourselves?

No. The Technology Framework is not a certification body. We implement the controls. An accredited assessor certifies CE, CE+ and ISO 27001.

What does it cost?

CE+ readiness from £2,950, fixed. ISO 27001 implementation from £15,000, scoped at diagnose. ISO 42001 readiness from £6,500. Assessor and audit fees are separate, paid to the accredited bodies.

Can a law firm say yes to AI safely?

Yes, once the controls are real. The work that satisfies the LAA and the insurer is the same work that makes AI safe to adopt: identity, access, data boundaries. From there, an AI Opportunity Audit shows where AI pays before you spend, and Microsoft Copilot readiness prepares the tenant.

Do you sell a fractional Head of IT for law firms?

Yes. Some firms outgrow the ticket queue and need the seat: a named Head of IT on the leadership team, from £4,750 a month. This page leads with the evidence work, and the seat is how the evidence stays owned.

08

Start the conversation

Bring the renewal date
Contact

Start the conversation.

The first conversation costs nothing and changes what happens next. Bring the legal aid renewal date, the PII proposal form, or the questionnaire that started this.

Proof you can dial

Call 0117 456 5486. The voice that answers is our own AI call agent, in production, on our own line. We run our practice on what we sell. Hear it running.

The call button dials the line above.

Talk to us